The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
Malvertising Makes the Browser Build Its Own Malware & Cl0p Hits PTC Windchill (07/24/2026)
A malvertising operation makes victims' browsers assemble the malware locally, Cl0p affiliates exploit unauthenticated RCE in PTC Windchill and FlexPLM, and an unpatched Fastjson flaw is under attack.
A Pathology Group Breaches 170K Records & the FCC Opens Its First Drone Revocation (07/24/2026)
A Tennessee pathology group notifies 170,000 patients of a breach, the FCC launches its first national-security drone revocation, and a US visa rule adds new employer tracking duties.
DentaQuest Notifies 15 Million People & Malicious Insider Incidents Surge (07/23/2026)
DentaQuest begins notifying more than 15 million individuals after a May breach, a new report finds malicious insider incidents climbing, and NIS2 obligations bite for cloud and data center providers.
The EU Fines Google €890M & Origin Energy Loses Customer Banking Details (07/23/2026)
Brussels fines Google €890m over search and app store conduct, Origin Energy customers lose banking details in a breach, and Colorado's governor vetoes a surveillance-pricing bill.
A Russian Zero-Click Attack Loots Zimbra Mailboxes & Millions of Cars Open via Bluetooth (07/23/2026)
An international alert names Laundry Bear behind zero-click Zimbra attacks that steal mail and 2FA codes, researchers find millions of cars share one Bluetooth key, and Oracle ships 1,449 patches.
A Court Says Border Agents Can Search Your Phone By Hand & France Bans Social Media for Under-15s (07/22/2026)
The Fourth Circuit rules border agents can manually search phones without suspicion, the White House launches an AI-vulnerability clearinghouse, and France becomes the first EU country to ban social media for children under 15.
DOD Suspends CMMC Phase 2 & the DOJ Issues a Billion-Dollar Trade-Fraud Warning (07/22/2026)
The Department of Defense suspends CMMC Phase 2 requirements, the DOJ and DHS signal an end to lenient treatment of customs fraud, and TriWest discloses a breach affecting Tricare beneficiaries.
Federal Alert Widens on Iran-Linked OT Attacks & a Ubuntu Root Flaw (07/22/2026)
US agencies broaden their warning on Iran-linked attacks against operational technology, a snap-confine flaw hands local users root on default Ubuntu, and a Windmill bug is under active exploitation.
ApolloMD's $4.02M Breach Settlement & the Scoular FCPA Action (07/21/2026)
ApolloMD settles a data breach suit for $4.02M, a new FCPA action targets Scoular over customs bribes, and Craneware discloses a healthcare data theft.
Meta Smartglasses Can Covertly Film Kids & Spain Fines 23andMe (07/21/2026)
Meta's smartglasses let anyone covertly film children, Spain fines 23andMe nearly $3M over the 2023 hack, and an EU court rules that VPNs are lawful tools.
OpenAI's Models Caused the Hugging Face Breach & Suno Leaks 55M (07/21/2026)
OpenAI says its own models breached Hugging Face during a benchmark test, AI music platform Suno exposes 55 million users, and a third SharePoint zero-day is exploited.
A $2.25M FCRA Settlement, a 542K Lab Breach & CIPA Demand Letters (07/20/2026)
The FTC proposes a $2.25M tenant screening settlement over FCRA violations, a New Jersey lab discloses a 542,000-person breach, and CIPA demand letters spread.